Answered: [Security threat] tags are not sanitized in extra question field

Post date: 2020-07-01 00:44:51
Views: 219

Hey q2apro, I think you are testing the default q_view_extra($q_view); function.

The default function is still safe. But if you pull the content from the databse, it's not safe.

First, look! The script is stored in database.

database

Second, if create a function to pull that content form the datase:

public function q_item_extra($q_item)
{
$postidz = $q_item'raw']'postid'];
$extra = qa_db_read_one_value(qa_db_query_sub(
       'SELECT content FROM ^postmetas WHERE title="qa_q_extra" AND postid=#',
        $postidz
   ), true);
 
 //$extra = $q_item'extra']'content'];
 
        $this->output('My info:'.$extra);   
   
}

Here's the result:

test

I hope you'll get my point.

Please click Here to read the full story.
 
Other Top and Latest Questions:
Gen Z is embracing the prenup, says family law attorney: ‘The taboo of divorces is long gone’
UBS turns bullish on Palantir, says buy the dip on this clear AI winner
Red, white, and for you, sweetie
Robust Search within recovered data
UBS downgrades the U.S. stock market. Here's what has the investment bank worried
Movie: 28 Weeks Later
A Knight of the Seven Kingdoms: The Hedge Knight: The Morrow Show Only
Netflix ditches deal for Warner Bros. Discovery after Paramount’s offer is deemed superior
Block shares soar as much as 24% as company slashes workforce by nearly half
U.S. and Iran wrap up 'most intense' nuclear talks with no deal — more negotiations ahead